Sceawere

Vulnerability Detail

CVE-2026-73703UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

HPE Networking Fabric Composer XSS

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
Fabric Composer
Attack Type
N/A
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-01T20:17:17.663Z",
  "pubdate": "2026-09-01T20:17:17.663Z",
  "executiveSummary": "A stored cross-site scripting (XSS) vulnerability exists within the web-based management interface of HPE Networking Fabric Composer.\nThis vulnerability allows an unauthenticated adjacent attacker to inject and persist malicious script code into the application interface.\nWhen an authorized user accesses the compromised page, the browser executes the injected script within the security context of the HPE Networking Fabric Composer domain.\nThe primary risk involves unauthorized execution of arbitrary client-side code, which may lead to session hijacking, unauthorized administrative actions, or data theft.\nThe vulnerability requires the attacker to be in an adjacent network position relative to the target interface.\nSuccessful exploitation compromises the integrity and confidentiality of the administrative session, potentially allowing an attacker to manipulate network configurations or view sensitive management data.\nThis flaw highlights a failure in input sanitization or output encoding mechanisms within the management platform's web interface, necessitating immediate attention to secure web development practices.",
  "technicalDetails": "The vulnerability is identified as a stored XSS flaw residing in the web-based management interface of HPE Networking Fabric Composer. The root cause is the improper sanitization and validation of user-supplied data before it is persisted in the application's underlying database or persistent storage and subsequently rendered in the victim's browser.\nExploitation occurs when an attacker crafts a malicious payload containing script code and transmits it to an input field within the web interface that is vulnerable to improper handling. Because the application fails to adequately encode the input, the malicious script is stored in the system. When a different authenticated user—typically an administrator—navigates to the page where this stored data is displayed, the application renders the script without proper escaping, causing the victim's browser to parse and execute the attacker's code.\nThe execution context is the origin of the HPE Networking Fabric Composer web interface, meaning the script operates under the legitimate session of the authenticated user. This allows the script to perform any action the user is authorized to execute, such as modifying fabric configurations, creating new administrative accounts, or intercepting sensitive session tokens and cookies. The attack vector is strictly limited to an adjacent attacker, meaning the threat actor must be on the same local network segment as the target management interface.\nThe attack flow follows a three-stage progression: First, the attacker identifies a persistent input field that does not properly sanitize HTML/JavaScript characters. Second, the attacker submits a payload—such as a document.cookie exfiltration script—to this field, which is then successfully written to the system’s backend storage. Third, the victim accesses the management interface, triggering the execution of the payload within the victim’s browser. The persistence of this attack ensures that any user visiting the affected page will trigger the malicious payload, making it an effective method for long-term monitoring or administrative compromise of the networking fabric management infrastructure."
}
CVE-2026-73703: HPE Networking Fabric Composer XSS (HIGH Severity, CVSS: 8.8) - Sceawere